cbcvebase.
CVE-2026-44938
published 2026-07-07

CVE-2026-44938: A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or…

PriorityP258high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.36%
28.4th percentile
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.comrancher_fleet>= 0.12.0 < 0.12.150.12.15
github.comrancher_fleet>= 0.13.0 < 0.13.110.13.11
github.comrancher_fleet>= 0.14.0 < 0.14.60.14.6
github.comrancher_fleet>= 0.15.0 < 0.15.20.15.2
suserancher>= 0.12.0 < 0.12.150.12.15
suserancher>= 0.13.0 < 0.13.110.13.11
suserancher>= 0.14.0 < 0.14.60.14.6
suserancher>= 0.15.0 < 0.15.20.15.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.